echoIRCd

Accounts & SASL

Registering a nickname creates an account you can protect, use to found channels, and log in with via SASL.

Register#

Message NickServ to register your current nick, then identify:

/msg NickServ REGISTER <password> <email>
/msg NickServ IDENTIFY <password>

SASL mechanisms#

SASL logs you in during connection, before you join anything. echoIRCd advertises:

MechanismHow it works
PLAINaccount + password
EXTERNALyour TLS client-certificate fingerprint
SCRAM-SHA-256salted challenge / response — no password on the wire
ECDSA-NIST256P-CHALLENGEsign a challenge with a NIST P-256 key

SASL EXTERNAL (client certificate)#

Add your certificate fingerprint to your account, then select EXTERNAL in your client:

/msg NickServ CERT ADD

Key-based login (ECDSA)#

Generate a NIST P-256 key and register its public half. At login the server sends a random challenge, your client signs it, and the signature is verified against the stored key — nothing secret crosses the wire.

ecdsatool keygen ~/.ecdsa.pem
ecdsatool pubkey ~/.ecdsa.pem
/msg NickServ SET PUBKEY <printed-public-key>

Then point your client's SASL settings at the key file and choose the ECDSA-NIST256P-CHALLENGE mechanism. See /msg NickServ HELP SET PUBKEY for more.